05 Oct
|
Triomics
|
Bengaluru
05 Oct
Triomics
Bengaluru
Role: DevSecOps Engineer
Location: Bangalore (4 days WFO)
Team: Product & Engineering
Reports to: Director of Compliance
About Triomics:
Triomics helps oncology organizations scale clinical research and high-quality data creation without scaling headcount. Our AI platform - powered by OncoLLM™- automates the operational work behind trial screening, eligibility interpretation, and oncology data abstraction across Prism (clinical trial matching), Harmony (oncology registry RWE curation), and Symphony (clinician copilot). Built for real-world hospital workflows, Triomics integrates with EHRs and CTMS systems and is deployed with leading academic cancer centers to improve speed, consistency, and audit-ready clinical accuracy.
Role Overview:
We are looking for a DevSecOps Engineer to help secure, harden, and maintain scalable, reliable infrastructure in a HIPAA-regulated, SOC 2-audited environment. In this role, you will work closely with engineering teams to build security into our cloud environments and deployment pipelines, and you will remediate security findings directly including in code.
This role works under the direction of the Compliance and Security function, which sets priorities, requirements, and remediation targets. You will sit with engineers, work in their repositories and pipelines, and ship changes through the same development process they use. You will be responsible for cloud security across Azure and AWS, securing CI/CD pipelines, managing the vulnerability lifecycle from detection through verified closure, and supporting incident response and compliance operations.
What You’ll Do:
- Secure and harden cloud environments Microsoft Azure and AWS: including identity and access management, network security, encryption, logging, and configuration baselines.
- Build security into CI/CD pipelines: secrets management, dependency and container scanning, SAST/SCA integration, and infrastructure-as-code review.
- Remediate findings from penetration tests, vulnerability scans,
and code analysis writing fixes in application code where practical and driving engineering teams to closure where not.
- Manage the vulnerability lifecycle: triage, prioritize, track remediation in Jira, and verify closure.
- Support incident response and root cause analysis: investigation, containment, and post-incident hardening.
- Automate security operations and compliance evidence collection supporting SOC 2 and HIPAA obligations.
- Collaborate with development teams to improve security posture without slowing delivery.
- Maintain clear documentation for security controls, processes, and operational procedures.
What We’re Looking For:
- 3–5 years of experience in DevOps, security engineering, or a related role.
- Robust hands-on experience with Azure and AWS (security services, Entra ID, networking);
- Proficiency in Python and Bash scripting able to read application code and write fixes, not just configure tools.
- Strong experience with Kubernetes, Docker, CI/CD tooling, VS Code.
- Solid understanding of Linux system administration, networking concepts, and security hardening practices.
- Familiarity with common vulnerability classes (OWASP Top 10) and remediation patterns.
- Experience with monitoring, logging, and incident response systems.
- Strong communication skills and the ability to document technical processes effectively.
Education:
- Bachelor’s degree in Computer Science, Engineering, Information Systems, Healthcare Informatics, Life Sciences, Business, or a related field.
- Equivalent practical experience in technical program management, product delivery, healthcare technology, or software engineering environments may be considered.
Nice to Have:
- Experience in healthcare,
health-tech, or AI/ML-driven products
- Prior experience in a startup or high-growth company
- Cloud security certification (AZ-500 or equivalent).
- Experience in a HIPAA, SOC 2, or otherwise regulated environment.
What Success Looks Like:
- New vulnerabilities stop reaching production: findings are caught in the pipeline or in QA
- Pen test and vulnerability findings remediated within SLA, with closure verified. Tests come back cleaner each cycle.
- Security controls built into pipelines that speed up releases instead of blocking them.
- Security discipline is built into how the team works: secure defaults, automated checks, and paved-road patterns mean the remediation backlog shrinks quarter over quarter
- Clear visibility for Compliance and Engineering on security posture, open risks, and remediation progress
Why Join Us?
- Impact at scale - The AI you build directly accelerates cancer research and improves patient outcomes worldwide
- Cutting-edge problems - You’ll work on some of the hardest and most interesting LLM engineering challenges in a highly regulated industry.
- World-class team - Collaborate with experts across AI, engineering, product, and oncology with best-in-industry compensation.
- Culture that ships - We’re a team that works hard and plays hard (company-sponsored retreats in Bali, Sri Lanka, Goa, and more)
Employment eligibility:
- Employment is subject to successful completion of applicable pre-employment verification, including identity, education, prior employment, references, and other role-relevant checks, conducted in accordance with applicable law.
Perks & Benefits:
- Lunch Provided at the Office – one less daily decision, one happier employee.
- Flexible Working Hours – we care about output, not clock-ins.
- Health Insurance – comprehensive coverage for you and your family.
- Zomato Meal Benefit – breakfast and dinner can be ordered when you come in early or leave late, because effort deserves fuel.
📌 DevSecOps Engineer (Bengaluru)
🏢 Triomics
📍 Bengaluru